← WordPress Vulnerabilities
WordPress security by component

MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings

MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings imports and displays MLS real estate listings through IDX functionality in WordPress.

MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings (mlsimport-idx-plugin-mls-plugin-for-real-estate-listings) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 4.3.

Plugin slug: mlsimport-idx-plugin-mls-plugin-for-real-estate-listings

CVE-2026-17515: MLSImport subscriber AJAX access exposes import logs and post metadata

MLSImport before 7.0.4 exposes an AJAX action without an authorization check or CSRF protection. Any authenticated user, including a Subscriber, can invoke it to read the plugin's import log and import-related metadata for arbitrary posts. This unscored record received deeper review because it gives a low-privilege account an information-disclosure primitive that may expose paths, import failures or listing metadata. The CNA does not disclose the AJAX action, parameters or handler function.

PublishedAug 05, 2026
Known safe version7.0.4
Published vulnerabilities for mlsimport-idx-plugin-mls-plugin-for-real-estate-listings
Safe version
Aug 05, 2026 CVE-2026-17515
MLSImport subscriber AJAX access exposes import logs and post metadata
MLSImport before 7.0.4 exposes an AJAX action without an authorization check or CSRF protection. Any authenticated user, including a Subscriber, can invoke it to read the plugin's import log and import-related metadata for arbitrary posts. This unscored record received deeper review because it gives a low-privilege account an information-disclosure primitive that may expose paths, import failures or listing metadata. The CNA does not disclose the AJAX action, parameters or handler function.
7.0.4
CVE4.3
NVDPending